DENTEDIT Payment integrity
Book a demo

Security & compliance

Isolation you can watch fail on purpose.

Every environment ships with two separate payer plans, because isolation that cannot be demonstrated is not isolation. Ask us to reach one plan’s data with the other’s credentials, live, on the call — and to show what the attempt left in the audit record.

Every read
Of member data recorded as it happens
No PHI
Reaches an AI model by default
Per plan
Separation by construction, not configuration
Your VPC
Deployment option with no data egress
IDENTITY

Identity comes from your directory

Who someone is, what role they hold and which plan they belong to are resolved from your identity provider — never from anything the request itself claims. SSO and OIDC, per tenant, on a certified relying-party library; no shared or standing credentials.

·No default or embedded secrets. A weak configuration refuses to start rather than running exposed.
·Not signed in and not entitled are different answers, so nobody is sent round a loop they cannot exit.
·A refusal never discloses what it refused — no name, no member number, no confirmation the record exists.
TENANCY

Your data, held apart from everyone else’s

Your own reference data — eligibility, plan design, contracted fees, accumulators, payment and authorisation history — is held separately from the industry content every plan shares. Ownership is checked where a fact is used, not only at the front door.

·Analytics and relationship data separated per plan, not filtered per plan.
·Attachments are scoped to the patient they belong to, per plan.
·Another member’s record cannot influence a decision — not merely cannot be displayed.

PHI

The access trail is capture, not a query.

A report that answers “who read this member’s record” from data nobody captured reads as nobody looked. So the record is written at the moment of the read, on every route that can return member information.

It covers every alternate form of the same request, so no path is a blind spot, and the entry is committed before the response leaves — whether the request succeeded or failed.

What the record holds

What was accessed, by whom, in what role, from where, and with what outcome — without copying the member information itself into the log, so the audit trail is not a second place PHI lives.

Append-only, with a stated failure policy

If the record cannot be written, an export is refused; a clinician’s read is not blocked. Coverage and gaps are published beside the report, so your auditor reads the trail’s completeness instead of assuming it.

Exports are events too

What left the platform, in what package, to whom — including the per-claim evidence package, whose every section carries its own status and reason rather than an empty list.

Deployment history

What was deployed, when, by whom, and what was rolled back — with rollbacks typed and counted rather than folded into a change log.

The AI boundary

De-identifying by default, and the disclosure names what was removed.

One audited boundary is the only place in the platform that can reach an AI provider. Everything else — editing, pricing, the trace, governance — runs with no provider connected at all.

Removed by what it says, not by where it sits

Identifiers hide inside sentences the platform itself wrote — a member number in the middle of an explanation. Removal is by content, not by field name, and the disclosure record names what was removed rather than asserting that nothing identifying left.

Every explanation re-verified

A plain-language explanation is checked back against the decision and the arithmetic before a reviewer ever sees it: every figure by value and by what the sentence says it is, and no sentence may promise an outcome the claim did not receive.

Your compliance officer can read it themselves

Which provider a deployment is using, what it is permitted to see, what is therefore enabled, and what has left the system — on one screen in the product, for your compliance officer to read rather than for us to describe.

Deployment posture

A process that says nothing is closed.

Anonymous access defaults to closed in production and the profile is logged at boot. On a closed instance no read answers without a session, and an unauthenticated submission needs a channel credential that binds it to exactly one tenant.

Both postures are verified independently before every release — including a deployment started with a deliberately failing data source, to prove a claim stops rather than adjudicating on facts nobody can vouch for.

Data integrity

Nothing is erased, and a retry is never a duplicate.

·A claim is never edited in place. Re-evaluation adds a new record; the previous recommendation stays readable.
·A decision is committed as one all-or-nothing step. A partial failure leaves nothing behind to reconcile by hand.
·A resend, a retry or a crash mid-flight can never produce two decisions or two payments for one claim.
·A malformed submission is rejected before it is recorded, so a bad file cannot block the good retry behind it.
·Review and appeal outcomes are written once and never overwritten; every rule version is a permanent record.

Assurance

We hand you the register of what is not proven yet.

Every part of this platform has been through independent adversarial review, and every confirmed finding is recorded with the window in which the control did not hold — not only the end state in which it does. Your risk committee is entitled to the second statement, and it is the harder one to make.

A known-limitations register ships with the product. Your diligence team gets it on day one, so nothing in it becomes a surprise found later by your auditor — or by a regulator.

What your diligence team receives

An architecture and data-flow document, the control set mapped to each commitment on this page, the known-limitations register, the disclosure history, and a live session in which any control on this page is demonstrated on request rather than attested on paper.

Sent before the first workshop — not held back for a later stage of the deal.
Demonstrated, not attested

A control that refuses because it works and a control that refuses because it is broken look identical from outside. We show you both sides on a live system, so you are judging evidence rather than a claim.

Findings carry their window

When something was wrong, we state what was reachable and for how long — the fact your breach analysis needs and the one vendors usually leave out.

Send your security questionnaire. We would rather answer it early.

Bring your privacy officer to the same call as your claims lead. The isolation demonstration takes ten minutes and it is the part of the demo people remember.

Book a demo How the engine works